Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2019-25087
Disclosure Date: December 27, 2022 (last updated February 24, 2025)
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The name of the patch is 1a0de56e4dafff9c2f9c8f6b130a764f7a50df52. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216863.
0
Attacker Value
Unknown
CVE-2019-5480
Disclosure Date: September 03, 2019 (last updated November 27, 2024)
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
0
Attacker Value
Unknown
CVE-2018-16478
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
0
Attacker Value
Unknown
CVE-2018-3787
Disclosure Date: August 31, 2018 (last updated November 27, 2024)
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
0
Attacker Value
Unknown
CVE-2018-16134
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
0
Attacker Value
Unknown
CVE-2018-16133
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
0
Attacker Value
Unknown
CVE-2018-3716
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
0
Attacker Value
Unknown
CVE-2006-1774
Disclosure Date: April 13, 2006 (last updated October 04, 2023)
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
0
Attacker Value
Unknown
CVE-2005-2982
Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
0
Attacker Value
Unknown
CVE-2004-2100
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
0